Trojan

Trojan:MSIL/ClipBanker.GD!MTB removal tips

Malware Removal

The Trojan:MSIL/ClipBanker.GD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/ClipBanker.GD!MTB virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:MSIL/ClipBanker.GD!MTB?


File Info:

crc32: 2DF0325B
md5: 8f37ab62a0bb9d3aa6d27ab74cbf2dee
name: 8F37AB62A0BB9D3AA6D27AB74CBF2DEE.mlw
sha1: f9ff943fe4374812e41d56a576783863378aeb90
sha256: 549e71ecce7c1c04bba1050f6005d93f89623a149e91f4aa76beedf9be5350f1
sha512: d0c31585efeabd0dacadb66c1a638a1afdb73f19ff1888aa58e28978d29846106a875e6699eed679b71e79c87ec1d0ddc989e12c01c40b1bbc2efc105653fe1d
ssdeep: 192:Nd4dYU+TwQvmlZhFsRQieV+RyqjSv+lEQ7:aGwQQFsRsiU+S
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: BTC Clipper.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Cracking Tool
ProductVersion: 1.0.0.0
FileDescription: Cracking Tool
OriginalFilename: BTC Clipper.exe

Trojan:MSIL/ClipBanker.GD!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.58245
FireEyeGeneric.mg.8f37ab62a0bb9d3a
CAT-QuickHealTrojan.MSIL
ALYacGen:Variant.Bulz.58245
CylanceUnsafe
ZillyaTrojan.ClipBanker.Win32.6805
AegisLabTrojan.MSIL.ClipBanker.7!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Bulz.58245
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34590.am0@aiUk06h
CyrenW32/Trojan.TVMF-0164
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.RC
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
AlibabaTrojanBanker:MSIL/ClipBanker.0e1f26d9
NANO-AntivirusTrojan.Win32.ClipBanker.ilozez
TencentMsil.Trojan-banker.Clipbanker.Eckl
Ad-AwareGen:Variant.Bulz.58245
SophosMal/Generic-S
ComodoMalware@#23hn6c07ddz7u
F-SecureTrojan.TR/Spy.ClipBanker.mfjqr
DrWebTrojan.ClipBankerNET.7
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.MSIL.CLIPBANKER.SM
McAfee-GW-EditionRDN/PWS-Banker
EmsisoftGen:Variant.Bulz.58245 (B)
IkarusTrojan.MSIL.ClipBanker
JiangminTrojan.Banker.MSIL.dpd
MaxSecureTrojan.Malware.73489558.susgen
AviraTR/Spy.ClipBanker.mfjqr
MAXmalware (ai score=88)
Antiy-AVLTrojan[Banker]/MSIL.ClipBanker
MicrosoftTrojan:MSIL/ClipBanker.GD!MTB
ArcabitTrojan.Bulz.DE385
AhnLab-V3Malware/Win32.RL_Trojanspy.C4222445
ZoneAlarmHEUR:Trojan-Banker.MSIL.ClipBanker.gen
GDataMSIL.Trojan-Stealer.ClipBanker.I
CynetMalicious (score: 85)
McAfeeRDN/PWS-Banker
MalwarebytesTrojan.ClipBanker
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.MSIL.CLIPBANKER.SM
RisingTrojan.ClipBanker!8.5FB (CLOUD)
YandexTrojan.ClipBanker!x52N2HvIfds
SentinelOneStatic AI – Malicious PE
FortinetMSIL/ClipBanker.LT!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.ClipBanker.HgIASOIA

How to remove Trojan:MSIL/ClipBanker.GD!MTB?

Trojan:MSIL/ClipBanker.GD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment